{"title":"Using CSP to model and analyze Transmission Control Protocol vulnerabilities within the broadcast network","authors":"H. Shahriari, R. Jalili","doi":"10.1109/INCC.2004.1366574","DOIUrl":null,"url":null,"abstract":"The spread of networks and their increasing complexity have complicated the task of security analysis. Accordingly, automatic verification approaches have received more attention recently. We have modeled a network, including a set of hosts (clients and servers), using the process algebra CSP (communicating sequential processes) in order to verify the Transmission Control Protocol (TCP) behavior against an active intruder. The model is verified using the FDR tool and, as a result, some attack scenarios which violate security are found. The scenarios show how an intruder can compromise the server trust to its clients. As the model is modular, extendable, and scalable, more complex attack scenarios (combinations of simple ones) can be detected using it.","PeriodicalId":337263,"journal":{"name":"2004 International Networking and Communication Conference","volume":"65 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2004-06-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"18","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2004 International Networking and Communication Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/INCC.2004.1366574","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 18
Abstract
The spread of networks and their increasing complexity have complicated the task of security analysis. Accordingly, automatic verification approaches have received more attention recently. We have modeled a network, including a set of hosts (clients and servers), using the process algebra CSP (communicating sequential processes) in order to verify the Transmission Control Protocol (TCP) behavior against an active intruder. The model is verified using the FDR tool and, as a result, some attack scenarios which violate security are found. The scenarios show how an intruder can compromise the server trust to its clients. As the model is modular, extendable, and scalable, more complex attack scenarios (combinations of simple ones) can be detected using it.